Lunar Spider
LUNAR SPIDER, also known as Gold Swathmore, is a Russian-speaking, financially motivated cybercriminal threat actor active since at least 2009. The group is assessed in the provided reporting as being behind the IcedID (BokBot) and Latrodectus malware families, and has continued operating despite law-enforcement disruption and leadership changes. One report states the group was previously led by Vyacheslav Igorevich Penchukov (aliases Tank, Zeus, Zevs, Father, TopBro), who was arrested in Switzerland in September 2022, extradited to the United States, and sentenced in 2024. The content links LUNAR SPIDER to malvertising, SEO poisoning, fake CAPTCHA/ClickFix delivery, and JavaScript-based infection chains. In an October 2024 campaign targeting the financial sector, the group used the heavily obfuscated Latrodectus JavaScript loader to deliver Brute Ratel C4. Victims searching for tax-related content were redirected to malicious JavaScript that downloaded an MSI installer, executed a malicious DLL via rundll32.exe, established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and communicated with attacker-controlled C2 domains. Separate reporting also states LUNAR SPIDER used Telegram on a FakeCaptcha panel to monitor victim clicks and send browser and visitor information through Telegram’s /sendMessage API. The provided content describes LUNAR SPIDER as an initial access broker within the cybercrime ecosystem. Reporting cited here assesses with high confidence that the group resumed operations after Operation Endgame disrupted IcedID infrastructure in May 2024, and that it has significant ties to ransomware operators. The content specifically mentions likely provision of initial access to WIZARD SPIDER, connections to ALPHV/BlackCat affiliates through shared infrastructure, and affiliations with Nemty (TRAVELING SPIDER) and TA2101 (TWISTED SPIDER). The reporting also notes that IcedID was made available to outside threat groups for ransomware campaigns and that Nemty and TA2101 leveraged IcedID for initial access. Infrastructure overlap is a recurring theme in the provided reporting. LUNAR SPIDER activity is described as using shared hosting and providers across IcedID and Latrodectus operations, including SHOCK-1 (ASN 395092), overlapping C2 infrastructure, and recurring SSL certificate issuer patterns such as "AU," "Some-State," and "Internet Widgits Pty Ltd." The content also states that analysts uncovered more than 200 malicious infrastructure elements associated with IcedID and Latrodectus and attributed them to LUNAR SPIDER.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Banks
- Financial Services
- Insurance
Tradecraft
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Observables
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lunar Spider is known for using Telegram as a channel for monitoring victim interactions with their FakeCaptcha panel, specifically in campaigns delivering the Latrodectus malware.
Lunar Spider is a Russian-speaking cybercriminal group behind IcedID and Latrodectus malware, using phishing and advanced delivery techniques for malware distribution and long-term intrusions.
Intrusion activity attributed/linked to Lunar Spider using a JavaScript lure (tax form) to deliver Brute Ratel, followed by multi-malware deployment, credential theft, lateral movement, and data exfiltration over an extended dwell time.
Cybercrime group associated with development and deployment of IcedID and Latrodectus; uses web-based social engineering (fake CAPTCHA) to drive malware infections.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.